Bitcoin Forum

Other => Beginners & Help => Topic started by: dogisland on April 03, 2013, 07:46:02 AM



Title: StrongCoin key leak.
Post by: dogisland on April 03, 2013, 07:46:02 AM
This is a thread to answer questions on the StrongCoin key and clue field leak.


Title: Re: StrongCoin key leak.
Post by: wopwop on April 03, 2013, 07:51:33 AM
this is me caring


Title: Re: StrongCoin key leak.
Post by: rme on April 03, 2013, 10:01:08 AM
this is me caring
+1


Title: Re: StrongCoin key leak.
Post by: anfedorov on April 03, 2013, 10:35:59 AM
Over the easter weekend due to a bug in the strongcoin interface hackers were able to access all encrypted private keys held on the Strongcoin server. This means for people who had weak passwords on their keys or people who had a lot of information in their clue field the BTC may have already been stolen.

This is a thread to answer questions on the StrongCoin key and clue field leak.

1) what was the bug? what do you mean by "interface"?
2) what are you doing to prevent such bugs from occurring again?
3) do you know of anyone's coins being stolen?


Title: Re: StrongCoin key leak.
Post by: Jurek on April 03, 2013, 10:39:51 AM
http://anonmgur.com/up/bd6ec316d9938298b9d5373fa3d08a37.png (http://anonmgur.com/up/bd6ec316d9938298b9d5373fa3d08a37.png)


Title: Re: StrongCoin key leak.
Post by: omgitsmehehe on April 03, 2013, 10:42:31 AM
I used StrongCoin once. Then I seen their 1% fee. Seriously? I can transfer my own money for free and more securely.


Title: Re: StrongCoin key leak.
Post by: manface on April 03, 2013, 10:55:53 AM
Can you explain what happened? I looked at strongcoin once but compared to blockchain.info they didn't seem to offer much.


Title: Re: StrongCoin key leak.
Post by: jago25_98 on April 03, 2013, 11:09:20 AM
I see I signed up for it at some point. Balance is zero. Perhaps it always was. Can't remember and there's no history. O well...

deja vu, never mind :p !


Title: Re: StrongCoin key leak.
Post by: dogisland on April 03, 2013, 11:31:36 AM
Over the easter weekend due to a bug in the strongcoin interface hackers were able to access all encrypted private keys held on the Strongcoin server. This means for people who had weak passwords on their keys or people who had a lot of information in their clue field the BTC may have already been stolen.

This is a thread to answer questions on the StrongCoin key and clue field leak.

1) what was the bug? what do you mean by "interface"?
2) what are you doing to prevent such bugs from occurring again?
3) do you know of anyone's coins being stolen?

1. It was possible to change the id in a URL and see another users encrypted key. That is now fixed.
2. I'm posting a notice on the site to advise people to use longer passwords. There was already a widget to give the user feedback as to how strong there password was.
3. Yes.


Title: Re: StrongCoin key leak.
Post by: 🏰 TradeFortress 🏰 on April 03, 2013, 11:35:21 AM
LOL, why would anyone want to use it exactly.

No.


Title: Re: StrongCoin key leak.
Post by: TheSeven on April 03, 2013, 11:57:49 AM
Over the easter weekend due to a bug in the strongcoin interface hackers were able to access all encrypted private keys held on the Strongcoin server. This means for people who had weak passwords on their keys or people who had a lot of information in their clue field the BTC may have already been stolen.

This is a thread to answer questions on the StrongCoin key and clue field leak.

1) what was the bug? what do you mean by "interface"?
2) what are you doing to prevent such bugs from occurring again?
3) do you know of anyone's coins being stolen?

1. It was possible to change the id in a URL and see another users encrypted key. That is now fixed.
2. I'm posting a notice on the site to advise people to use longer passwords. There was already a widget to give the user feedback as to how strong there password was.
3. Yes.

This sounds like the whole source code of the site should undergo a very tight review and penetration testing ASAP.


Title: Re: StrongCoin key leak.
Post by: tiptopgemdotcom on April 03, 2013, 12:08:34 PM
Over the easter weekend due to a bug in the strongcoin interface hackers were able to access all encrypted private keys held on the Strongcoin server. This means for people who had weak passwords on their keys or people who had a lot of information in their clue field the BTC may have already been stolen.

This is a thread to answer questions on the StrongCoin key and clue field leak.

1) what was the bug? what do you mean by "interface"?
2) what are you doing to prevent such bugs from occurring again?
3) do you know of anyone's coins being stolen?

1. It was possible to change the id in a URL and see another users encrypted key. That is now fixed.
2. I'm posting a notice on the site to advise people to use longer passwords. There was already a widget to give the user feedback as to how strong there password was.
3. Yes.

This sounds like the whole source code of the site should undergo a very tight review and penetration testing ASAP.

^THIS


Title: Re: StrongCoin key leak.
Post by: tkbx on April 03, 2013, 01:08:38 PM
As far as online wallets go, StrongCoin seems pretty secure, but is there any legitimate reason to use an online wallet?

(Unless you were stupid enough to buy a Chromebook, then I have no sympathy for you)


Title: Re: StrongCoin key leak.
Post by: dogisland on April 03, 2013, 01:14:18 PM
As far as online wallets go, StrongCoin seems pretty secure, but is there any legitimate reason to use an online wallet?

(Unless you were stupid enough to buy a Chromebook, then I have no sympathy for you)

Benefits are.

1. Ease of use, nothing to install.
2. You don't have to do your own backups.
3. Accessible from anywhere.


Title: Re: StrongCoin key leak.
Post by: MPOE-PR on April 03, 2013, 01:19:56 PM
1. It was possible to change the id in a URL and see another users encrypted key. That is now fixed.

You're an idiot however, and that's not fixable. Who codes like that?!


Title: Re: StrongCoin key leak.
Post by: Jan on April 03, 2013, 01:26:42 PM
It is going to be interesting the day that blockchain.info leaks encrypted wallets. I wonder how many out of their 175.000 wallets use insecure passwords.


Title: Re: StrongCoin key leak.
Post by: kokojie on April 03, 2013, 01:46:45 PM
1. It was possible to change the id in a URL and see another users encrypted key. That is now fixed.

You're an idiot however, and that's not fixable. Who codes like that?!

+1


Title: Re: StrongCoin key leak.
Post by: hamdi on April 03, 2013, 01:48:42 PM
It is going to be interesting the day that blockchain.info leaks encrypted wallets. I wonder how many out of their 175.000 wallets use insecure passwords.
Already happened!


Title: Re: StrongCoin key leak.
Post by: ErebusBat on April 03, 2013, 01:55:46 PM
It is going to be interesting the day that blockchain.info leaks encrypted wallets. I wonder how many out of their 175.000 wallets use insecure passwords.
Already happened!
Sauce?


Title: Re: StrongCoin key leak.
Post by: Cryptoc on April 03, 2013, 01:57:19 PM
It is going to be interesting the day that blockchain.info leaks encrypted wallets. I wonder how many out of their 175.000 wallets use insecure passwords.
Already happened!
Any more information?


Title: Re: StrongCoin key leak.
Post by: pelleb on April 03, 2013, 02:04:28 PM
There is another problem.

The App uses 2 external JS for google analytics and mixpanel. While these are both trustworthy companies, basically a bad actor there could monitor passwords and private keys.

I'd recommend that any browser wallet not include any externally controlled javascripts.

P


Title: Re: StrongCoin key leak.
Post by: jp on April 03, 2013, 02:31:10 PM
Quote
1. It was possible to change the id in a URL and see another users encrypted key. That is now fixed.

I'd like a little more transparency please. While using your service, you made it sound that no one would know the private key because it was encrypted with your the user's password for that specific key. Even if someone could view another persons account page, how would they still have access to the key since they don't know the password to the encrypted key?

Thanks and sorry you're going through the growing pains here.


Title: Re: StrongCoin key leak.
Post by: dogisland on April 03, 2013, 02:37:11 PM
Quote
1. It was possible to change the id in a URL and see another users encrypted key. That is now fixed.

I'd like a little more transparency please. While using your service, you made it sound that no one would know the private key because it was encrypted with your the user's password for that specific key. Even if someone could view another persons account page, how would they still have access to the key since they don't know the password to the encrypted key?

Thanks and sorry you're going through the growing pains here.


They could see the key, but it was still AES 256 encrypted. So they would see something like

U2FsdGVkX19ZvPGX+4T98zGnTjwKs1CmkzXpm8fEJjzuubAY/3wg1JoC6BcqiqR6
mKhdlqyLTeRHc59VfW9ebfwWOfOKnK9qqN8TXXSL4Nw=

So the issue here is that if a user had a low quality password and had given extra info in the clue field then there is a chance they have lost coins.


Title: Re: StrongCoin key leak.
Post by: dansmith on April 03, 2013, 03:13:02 PM
Quote
1. It was possible to change the id in a URL and see another users encrypted key. That is now fixed.

By "encrypted key" you mean the encrypted password which is used to log into one's account? If so, were usernames leaked as well?


Title: Re: StrongCoin key leak
Post by: whiskers75 on April 03, 2013, 03:17:49 PM
For the record: blockchain.info/wallet (http://blockchain.info/wallet) stores your wallet locally and on their servers, encrypted at both places and only ever decrypted on your computer. Looks like StrongCoin was a bit late to the party.  :P
And it doesn't charge a 1% fee.
And you can do 'off-site backups' by email, Dropbox and Google Drive - yes, you can keep your wallet.
Blockchain.info wins!
(and it doesn't leak keys  :-\)


Title: Re: StrongCoin key leak.
Post by: dogisland on April 03, 2013, 03:20:42 PM
Quote
1. It was possible to change the id in a URL and see another users encrypted key. That is now fixed.

By "encrypted key" you mean the encrypted password which is used to log into one's account? If so, were usernames leaked as well?

I mean a bitcoin private key encrypted in AES 256. The AES 256 encryption is performed on the client side (javascript) using a password the user supplies. I never see that password.

So basically in StrongCoin when a private key is created, it is create in the browser. The user supplies a password to the Javascript and then Javascript AES encrypts the private key before sending it to the server.

So we only have AES encrypted private keys and a clue field. The user could supply a clue to help them remember the password. Some users may have given too much information in the clue field.

The AES encrypted key (still protected) was leaked along with the clue field.

The clue field has now been removed from Strongcoin and a warning added to encourage users to create more secure passwords.


Title: Re: StrongCoin key leak
Post by: dogisland on April 03, 2013, 03:25:32 PM
Looks like StrongCoin was a bit late to the party. 

We were around before Blockchain.info i.e. 2011 https://bitcointalk.org/index.php?topic=36169.0


Title: Re: StrongCoin key leak.
Post by: dansmith on April 03, 2013, 03:40:15 PM
Thank you for explaining.
So, I guess that your web app has full access to all tables of your DB?

What do you think about creating a separate DB user for each wallet account. This way there will be no way a user could see other users' tables. Certainly, this will kill DB performance. But who cares about performance when money is at stake?


Title: Re: StrongCoin key leak.
Post by: MPOE-PR on April 03, 2013, 07:30:06 PM
There is another problem.

The App uses 2 external JS for google analytics and mixpanel. While these are both trustworthy companies, basically a bad actor there could monitor passwords and private keys.

I'd recommend that any browser wallet not include any externally controlled javascripts.

P

Quote
19 (http://mpex.co/faq.html#19). Do you use Google Analytics ?
No. Making a BTC financials website and then slapping GA on it is really akin to going to a cancer survivor's survival party and bringing them chemo drugs as a gift. Yes, it's that insulting/thoughtless. Really. Yes, it does show that level of outright contempt for the user. Really.

Also GA does break Tor in many cases.

Will people read FAQs? Will people implement the better solutions as demonstrated? Etc.


Title: Re: StrongCoin key leak.
Post by: springy on April 03, 2013, 07:34:59 PM
1. It was possible to change the id in a URL and see another users encrypted key. That is now fixed.

You're an idiot however, and that's not fixable. Who codes like that?!

Agree, laziness and ego got in the way I think!


Title: Re: StrongCoin key leak
Post by: jonitas on April 04, 2013, 09:48:54 PM
And it doesn't charge a 1% fee.

Ok, so how do I get my money out without paying the 1% fee? I go to Blockchain.info -> import/export -> import -> import private key ? Will that transfer my wallet to blockchain and leave the wallet I already have in the same account alone?

Just checking because I donīt want to overwrite any current balance I have.

I guess my password was strong enough because I still have all of my bitcoins that I hold at strongcoin. But due to the increased price of bitcoin I should definitely diversify into more wallets.


Title: Re: StrongCoin key leak.
Post by: gjk on April 07, 2013, 10:44:25 AM
...I tried to send my money to other BTC-adresses, but everytime a warning namend "undefinded" occured. What's wrong?  ???

I also asked via mail, but I didnt get an answer yet (one week ago).  :-\


Title: Re: StrongCoin key leak.
Post by: aussie_striker on May 16, 2013, 10:32:40 AM
I changed my password after this happened and it stated around 4 years to break it. Today I looked at my account and there is a transaction that cleared out my whole account (5.48134 BTC) 4 days ago.
Needless to say I'm not happy about it.

I've looked at my strongcoin and also on bitchain, not sure why but it shows a different address it went to or am I reading that wrong?

According to Strongcoin
From 1JE5dWuwo7z67VAAgzrfRUiNpvHsenhW5U
To    1PKSK8TyvQrCGjQbsbNVQNoo4ftcEiBUSk
   - 5.48 134

On Blockchain it shows
1GKVf2b4QTV3TzBUWFzT5FQbmhKBPU861m 5.48134135 BTC

Not sure if it is due to the same problem or there is a new problem. I've changed passwords again but now have nothing.




Title: Re: StrongCoin key leak.
Post by: vesperwillow on August 22, 2013, 02:06:47 PM
1. It was possible to change the id in a URL and see another users encrypted key. That is now fixed.

You're an idiot however, and that's not fixable. Who codes like that?!

Here's the most valuable question in this thread: Who's the babe in your profile pic??